Junglewise Threat Intelligence

CVE-2026-18859: ESAFENET CDG SQL injection in usbkey login

CVE-2026-18859 · Severity: high · CVSS 7.3 · Published 2026-08-05

Executive brief

ESAFENET CDG is a web-based component used for digital credential and key management in enterprise environments. A SQL injection vulnerability in the USB key login function allows remote attackers to manipulate database queries through the keyid parameter, potentially exposing sensitive credential data or bypassing authentication mechanisms without requiring prior access or credentials.

Technical details

This vulnerability is a SQL injection flaw in the /CDGServer3/ukey/usbkey;logindojo endpoint of ESAFENET CDG. The vulnerability exists because user-supplied input in the keyid parameter is not properly sanitized before being used in SQL queries. An attacker can exploit this over the network by crafting malicious SQL payloads in the keyid argument to manipulate database operations. The attack requires no authentication and the exploit is publicly available. Patches from the vendor are not currently available as the vendor did not respond to early disclosure notification.

Affected products

  • ESAFENET CDG up to 20260615

Timeline

  • 2026-08-05: disclosed
  • other: Exploit code is publicly available

References